Description
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.
Products
- FreeBSD 4.0
 - FreeBSD 4.0 Alpha
 - FreeBSD 4.1.1
 - FreeBSD 4.1.1 Release
 - FreeBSD 4.1
 
Questions to Ask Vendors
- Can you confirm whether your systems are affected by CVE-2000-1066, and if so, what steps are you currently taking to mitigate this vulnerability?
 - What is your estimated timeline for fully resolving CVE-2000-1066 in your products or services, and how will you communicate updates on this issue to us as your customer?
 
Recommended Actions
- Check out the advisory links provided below.
 
References